Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2009-4751
SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2009-4752
PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RIESGO
abrir
Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RIESGO
abrir
Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RIESGO
abrir
Referência
CVE-2013-5045
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RIESGO
abrir
ReferênciaVexDay Proof
BaoFeng - ActiveX 'OnBeforeVideoDownload()' Remote Buffer Overflow
CVE-2009-1612remotewindows
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote
50RIESGO
abrir
Referência
CVE-2026-9523
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection
33RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2022-41082
CVE-2022-41082HIGHbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2025-59287
CVE-2025-59287CRITICALbajo ataque
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2011-4106
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a
28RIESGO
abrir
Referência
CVE-2015-1427
CVE-2015-1427CRITICALbajo ataque
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Referência
CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
ReferênciaVexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
CVE-2009-2081webappsphp
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir
ReferênciaVexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
CVE-2009-2095webappsphp
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RIESGO
abrir
Referência
CVE-2011-4800
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and wri
23RIESGO
abrir
Referência
CVE-2022-41040
CVE-2022-41040HIGHbajo ataqueransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RIESGO
abrir
Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
ReferênciaVexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
CVE-2009-2110webappsphp
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RIESGO
abrir
Referência
CVE-2011-4812
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2026-9434
Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9431
Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow
41RIESGO
abrir
Referência
CVE-2013-6987
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RIESGO
abrir
Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RIESGO
abrir
Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
ReferênciaVexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
CVE-2009-2166webappsphp
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RIESGO
abrir
anteriorpágina 582 / 753siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.